Emerging news, clearly reported.

Independent · Evidence-first · Developing stories

CISA Adds Arista and Fortinet Flaws to Exploited List

WSOI editorial graphic for CISA adding Arista and Fortinet vulnerabilities to its exploited-vulnerability catalog.

Summary

U.S. cybersecurity authorities added vulnerabilities affecting Arista VeloCloud Orchestrator and Fortinet FortiOS to the federal Known Exploited Vulnerabilities catalog on July 27. The action sets near-term remediation deadlines for federal agencies and gives other operators a verified signal to prioritize review.

WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency added two network-appliance vulnerabilities to its Known Exploited Vulnerabilities catalog on Monday, July 27, directing federal civilian agencies to prioritize remediation of affected Arista and Fortinet products.

The entries cover CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem and CVE-2025-68686 in Fortinet FortiOS. The National Vulnerability Database records both entries as actively exploited and lists federal remediation dates of July 30 for the Arista flaw and August 10 for the Fortinet flaw.

CISA’s catalog is not a prediction that every affected installation has been compromised. It is a risk-prioritization tool based on evidence that attackers have used a vulnerability in real activity. Federal deadlines apply to covered civilian agencies, while private and state operators commonly use the catalog as a signal for patch planning.

Arista flaw carries the more urgent deadline

Arista’s Security Advisory 0144 describes CVE-2026-16812 as an operating-system command-injection issue in on-premises VeloCloud Orchestrator deployments. The company assigned the vulnerability a 10.0 severity score and said successful exploitation could compromise the confidentiality, integrity and availability of the orchestrator and the data it manages.

The vendor said functionality intended only for internal use could be reached remotely. It also said the issue was discovered externally and was known to be actively exploited. Hosted and dedicated versions had been patched before the advisory was published, while operators of affected on-premises versions were directed to upgrade to fixed releases.

The NVD lists affected release ranges beginning with 5.2.0, 6.1.0 and 6.4.0, with fixed versions varying by branch. Administrators should use Arista’s advisory rather than a generalized version statement because the applicable upgrade depends on the installed release line.

Fortinet issue depends on an earlier compromise

CVE-2025-68686 affects multiple FortiOS branches. The NVD description says an unauthenticated remote attacker could bypass a patch related to malicious symbolic-link persistence through crafted HTTP requests. However, it also states that an attacker must first have compromised the device at the filesystem level through another vulnerability.

That prerequisite matters. The Fortinet issue is not described as a standalone initial-access path, but it can help an attacker retain or recover access to sensitive information after another compromise. The vendor-assigned severity score listed by NVD is 5.9, lower than the Arista flaw’s 10.0, but demonstrated exploitation is the reason both received federal priority.

What operators should verify

The immediate task is inventory: organizations need to determine whether they run affected on-premises VeloCloud Orchestrator or FortiOS versions, whether those systems are exposed to the internet and whether vendor mitigations or upgrades have been applied. Arista also published indicators and forensic guidance for customers investigating possible exploitation.

The confirmed deadlines are July 30 for the Arista entry and August 10 for the Fortinet entry. Those dates should not be inferred from secondary summaries; one report incorrectly listed July 20 for Arista, a date before the catalog addition. The official NVD record reflecting CISA data lists July 30.

Key Facts

  • CISA added both vulnerabilities to the Known Exploited Vulnerabilities catalog on July 27, 2026.
  • CVE-2026-16812 affects Arista VeloCloud Orchestrator On-Prem and carries a vendor score of 10.0.
  • The Arista federal remediation date is July 30, 2026.
  • CVE-2025-68686 affects multiple FortiOS versions and requires an earlier filesystem-level compromise.
  • The Fortinet federal remediation date is August 10, 2026.

Sources

  1. Arista Networks. “Security Advisory 0144.” Primary. Published July 27, 2026. https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144. Accessed July 29, 2026. Supports the vulnerability description, severity, active-exploitation statement, affected deployments and fixed versions.
  2. National Institute of Standards and Technology, National Vulnerability Database. “CVE-2026-16812 Detail.” Primary government database. Published July 27, 2026; modified July 28, 2026. https://nvd.nist.gov/vuln/detail/CVE-2026-16812. Accessed July 29, 2026. Supports the CISA catalog status, July 30 due date and affected release ranges.
  3. National Institute of Standards and Technology, National Vulnerability Database. “CVE-2025-68686 Detail.” Primary government database. Published February 10, 2026; modified July 28, 2026. https://nvd.nist.gov/vuln/detail/CVE-2025-68686. Accessed July 29, 2026. Supports the CISA addition, August 10 due date, affected FortiOS versions and prior-compromise requirement.
  4. Security Affairs. “U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog.” Secondary. Published July 28, 2026. https://securityaffairs.com/196130/security/u-s-cisa-adds-arista-velocloud-orchestrator-and-fortinet-fortios-flaws-to-its-known-exploited-vulnerabilities-catalog.html. Accessed July 29, 2026. Independently supports the catalog additions; its incorrect Arista deadline was not used.

Publication note

Published from information verified through July 29, 2026. This article may be updated if material facts change.